CVE-2022-4449

Page Scroll To ID < 1.7.6 - Contributor+ Stored XSS

The Page scroll to id WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.


We have discovered 8,094 live websites that are affected by CVE-2022-4449.

Run a Free Instant Scan




Affected Software

Product  Page Scroll To Id
Category Wordpress Plugins
Vulnerable Domains8,094 live websites (18% of Page Scroll To Id install base)
Vulnerable Versions
  • from 0 through 1.7.6
Vulnerable Versions Count23 versions ( 85% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jan 16, 2023
  • Updated - Apr 7, 2025

Credits

  • Lana Codes (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2022-4449
United States1,476 websites



Germany990 websites
Poland604 websites
Italy493 websites
France404 websites
GB281 websites
Russia262 websites
Czech Republic261 websites
Netherlands206 websites
Japan205 websites

Website Distribution by TLD

Number of websites using CVE-2022-4449
.com2,712 websites
.de622 websites
.pl434 websites
.it331 websites
.org245 websites
.cz232 websites
.ru206 websites
.nl180 websites
.com.br180 websites
.fr158 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-4449

Top websites that are affected by CVE-2022-4449. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com Singapore**,***
******.com Turkey**,***
*************.hu Hungary***,***
***.hu Hungary***,***
****.*********.com United States***,***
*************.com Ireland***,***
***.********.gov United States***,***
***********.com United States***,***
******.ro Romania***,***
**********.com United States***,***
See full domain list

FAQ

CVE-2022-4449 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Page Scroll To Id
A total of 8,094 websites have been identified as vulnerable to CVE-2022-4449, based on global website indexing conducted by WebTechSurvey.
The Page Scroll To Id is affected by the CVE-2022-4449 vulnerability.
Page Scroll To Id versions up to 1.7.6 are vulnerable to CVE-2022-4449.
CVE-2022-4449 is resolved in version 1.7.6 of Page Scroll To Id.